CWE-521
259 CVEs • Abstraction: Base
Weak Password Requirements
The product does not require that users should have strong passwords, which makes it easier for attackers to compromise user accounts.
CVEs (259)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Schneider Electric 65500ac2 Firmware 5500nac2 Firmware5500nac Firmware+3 moreJun 17, 2026 Jan 30, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A CWE-521: Weak Password Requirements vulnerability exists that could allow an attacker to gain control of the device when the attacker brute forces the password. Affected Products: C-Bus Network Automation Controller -...Show more |
Weak Password Requirements in GitHub repository publify/publify prior to 9.2.10. |
Weak Password Requirements in GitHub repository froxlor/froxlor prior to 2.0.10.
|
Weak Password Requirements in GitHub repository thorsten/phpmyfaq prior to 3.1.10. |
Kiwi TCMS is an open source test management system. In version 11.6 and prior, when users register new accounts and/or change passwords, there is no validation in place which would prevent them from picking an easy to gu...Show more |
Beijing Zed-3 Technologies Co.,Ltd VoIP simpliclty ASG 8.5.0.17807 (20181130-16:12) has a Weak password vulnerability. |
A default username and password for an administrator account was discovered in ZKTeco ZKTime 10.0 through 11.1.0, builds 20180901, 20190510.1, 20200309.3, 20200930, 20201231, and 20210220. |
Lazy Mouse server enforces weak password requirements and doesn't implement rate limiting, allowing remote unauthenticated users to easily and quickly brute force the PIN and execute arbitrary commands. CVSS:3.1/AV:N/AC:...Show more |
Nextcloud Server is an open source personal cloud server. Prior to versions 23.0.11, 24.0.7, and 25.0.0, there is no password length limit when creating a user as an administrator. An administrator can cause a limited Do...Show more |
Siyucms v6.1.7 was discovered to contain a remote code execution (RCE) vulnerability in the background. SIYUCMS is a content management system based on ThinkPaP5 AdminLTE. SIYUCMS has a background command execution vulne...Show more |
Weak Password Requirements in GitHub repository thorsten/phpmyfaq prior to 3.1.8. |
Weak Password Requirements in GitHub repository ikus060/rdiffweb prior to 2.5.0a4. |
Weak Password Requirements in GitHub repository ikus060/rdiffweb prior to 2.4.9. |
Weak Password Requirements in GitHub repository ikus060/minarca prior to 4.2.2. |
Weak Password Requirements in GitHub repository ikus060/rdiffweb prior to 2.4.2. |
HCL iNotes is susceptible to a Broken Password Strength Checks vulnerability. Custom password policies are not enforced on certain iNotes forms which could allow users to set weak passwords, leading to easier cracking. |
RuoYi v3.8.3 has a Weak password vulnerability in the management system. |
Tabit - password enumeration. Description: Tabit - password enumeration. The passwords for the Tabit system is a 4 digit OTP. One can resend OTP and try logging in indefinitely. Once again, this is an example of OWASP: A...Show more |
Weak Password Requirements in GitHub repository notrinos/notrinoserp prior to 0.7. |
Mealie 1.0.0beta3 employs weak password requirements which allows attackers to potentially gain unauthorized access to the application via brute-force attacks. |